threat
engine
.sh
Back
·
··:··
Home
/
Product
/
xstream
Product
xstream
37 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2022-41966
< 1.4.20
XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the appli
8.2
HIGH
CVE-2022-40152
< 1.4.20
Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the pars
6.5
MEDIUM
CVE-2022-40151
< 1.4.20
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user su
6.5
MEDIUM
CVE-2021-43859
< 1.4.19
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote att
7.5
HIGH
CVE-2021-39152
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5
HIGH
CVE-2021-39150
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5
HIGH
CVE-2021-39140
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
6.5
MEDIUM
CVE-2021-39154
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5
HIGH
CVE-2021-39153
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5
HIGH
CVE-2021-39151
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5
HIGH
CVE-2021-39149
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5
HIGH
CVE-2021-39148
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5
HIGH
CVE-2021-39147
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5
HIGH
CVE-2021-39146
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5
HIGH
CVE-2021-39145
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5
HIGH
CVE-2021-39144
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5
HIGH
CVE-2021-39141
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5
HIGH
CVE-2021-39139
< 1.4.18
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote
8.5
HIGH
CVE-2021-29505
< 1.4.17
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may al
7.5
HIGH
CVE-2021-21351
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability m
5.4
MEDIUM
CVE-2021-21350
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.3
MEDIUM
CVE-2021-21349
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
6.1
MEDIUM
CVE-2021-21348
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.3
MEDIUM
CVE-2021-21347
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
6.1
MEDIUM
CVE-2021-21346
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
6.1
MEDIUM
CVE-2021-21345
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.8
MEDIUM
CVE-2021-21344
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.3
MEDIUM
CVE-2021-21343
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.3
MEDIUM
CVE-2021-21342
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability w
5.3
MEDIUM
CVE-2021-21341
< 1.4.16
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability whi
7.5
HIGH
CVE-2020-26259
< 1.4.15
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitr
6.8
MEDIUM
CVE-2020-26258
< 1.4.15
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Requ
6.3
MEDIUM
CVE-2020-26217
< 1.4.14
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrar
8.0
HIGH
CVE-2019-10173
all versions
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the sec
9.8
CRITICAL
CVE-2013-7285
<= 1.4.6
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attack
9.8
CRITICAL
CVE-2017-7957
<= 1.4.9
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive
7.5
HIGH
CVE-2016-3674
< 1.4.9
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) Sjs
7.5
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin